Remote Cyber security Jobs · Application Security

Job listings

$98,000–$116,000/yr

  • Integrate AppSec tools into CI/CD pipelines and manage application security vulnerabilities.
  • Monitor and respond to security incidents, tuning WAF policies and security rulesets.
  • Collaborate with IT partners to perform security reviews and remediate findings across cloud platforms.

EMCOR Group, Inc. is a Fortune 500 leader in mechanical and electrical construction, industrial and energy infrastructure, and building services. As a large company with a diverse portfolio, it emphasizes a culture of security and collaboration.

  • Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects.
  • Triage and validate bug bounty reports, assess severity, and coordinate remediation with engineering.
  • Build and operate security automation including AI-assisted code review, scanning, and findings-triage pipelines.

RootstockLabs builds Bitcoin-secured DeFi infrastructure enabling companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale. They operate at the intersection of crypto and institutional finance with a global, diverse team.

US 5w PTO

  • Perform security center duties to secure third-party applications and devices, including vulnerability identification and patch management.
  • Review vulnerability scans, assess risks, and collaborate with technical teams and SMEs to remediate security issues.
  • Manage small to medium security projects and resolve application security problems while documenting activities.

OHSU is Oregon's only public academic health center, combining patient care, groundbreaking research, and training for the next generation of health care professionals. As Portland's largest employer, OHSU offers opportunities across hospitals and clinics in Oregon and Southwest Washington, with a culture welcoming all backgrounds.

$104,300–$193,700/yr

  • Collaborate with DevOps and engineering teams to embed security throughout the software development lifecycle.
  • Implement automated security testing, including SAST, DAST, SCA, and container security, and strengthen cloud-native security controls.
  • Support compliance with PCI-DSS, GDPR, CCPA, and SOC 2, and evaluate secure adoption of AI-assisted coding tools.

Our partner is a technology company in the travel and hospitality industry. They have a collaborative remote culture and value employee development and diversity.

  • Own and execute application, cloud, and API security across the platform.
  • Build detection, response, and hardening for a high-scale SaaS environment.
  • Collaborate with engineers to embed security into the SDLC and enterprise client requirements.

YGO.ai is a VC-funded AI tourism platform that provides AI search and recommendation engines for major travel enterprises. As a VC-funded startup, we maintain a hands-on, engineering-driven culture where security is integral from the start.

Unlimited PTO

  • Assess ServiceNow instance configurations against security baselines and identify misconfigurations.
  • Triage and validate customer-reported security findings related to instance configuration.
  • Partner with cross-functional teams to resolve complex security issues and drive systemic improvements.

ServiceNow is the AI control tower for business reinvention, enabling AI-powered workflows for enterprises. The company serves 85% of the Fortune 500 and fosters an AI-native culture focused on innovation and talent.

  • Walk through your approach to integrating security into CI/CD pipelines during feature development.
  • Describe how you handle vulnerability verification in production environments.
  • React to technical scenarios involving application security threats and balancing feature velocity.

Terac is building the world's largest pool of vetted human experts for AI. Researchers, AI labs, and product teams use Terac to recruit, screen, and pay study participants across industries, languages, and skill sets.

  • Conduct manual penetration tests against core systems and AI systems, and build AI-assisted tooling to extend testing coverage.
  • Help define how we pentest AI, including LLM applications, agents, and agent-generated code.
  • Triage findings from SAST tools, fix vulnerabilities, and tune rules to reduce false positives.

Forward Financing is a fintech company that unlocks capital for small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work.

$97,090–$133,590/yr

  • Partner with product and engineering teams to identify application security risks and frame them as clear business risks, launch options, and recommended next steps.
  • Read application code, configuration, pull requests, logs, and documentation to understand how systems work and where security risks may exist.
  • Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows and reduce recurring issues.

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. The company is remote-first with a people-first culture, offering competitive benefits and equity rewards.

$165,000–$200,000/yr
US Unlimited PTO

  • Lead the long-term technical strategy for offensive security, including red teaming and adversary simulations.
  • Conduct deep-dive vulnerability research and partner with DevOps to build automated security guardrails.
  • Mentor senior and mid-level engineers to foster a security-minded development culture.

Greenlight is a family technology company that helps families raise financially smart kids through its suite of products including the Greenlight app, debit card, and safety features. With over 6.5 million family members, Greenlight fosters a culture of innovation and collaboration to make family life easier.